CVE-2010-3035
Last modified
CVE-2010-3035 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.. CISA has confirmed active exploitation in the wild. EPSS estimates a 5.56% chance of exploitation in the next 30 days.
Description
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | >= 3.4.0, <= 3.9.1 |
References
- http://osvdb.org/67696Broken Link
- http://secunia.com/advisories/41190Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlBroken Link, Vendor Advisory
- http://www.securitytracker.com/id?1024371Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443VDB Entry, Vendor Advisory
- http://osvdb.org/67696Broken Link
- http://secunia.com/advisories/41190Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlBroken Link, Vendor Advisory
- http://www.securitytracker.com/id?1024371Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443VDB Entry, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3035US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2010-3035?
How severe is CVE-2010-3035?
How do I fix CVE-2010-3035?
Are you affected by CVE-2010-3035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
